Knplabs maintains a narrowly scoped portfolio centered on the Snappy compression library, a component embedded across storage and data-processing systems where serialized object handling is fundamental to its design. The recurring vulnerability signal reflects untrusted deserialization risks inherent to object-oriented compression workflows. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Knplabs over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-28115CRITICAL Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.4.2, Snappy is vulnerable to PHAR deserialization due to a lack | Mar 17, 2023 | 9.8 | 31 | NO | NO |
CVE-2023-41330CRITICAL knplabs/knp-snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page.
## Issue
On March 17th the vulnerability CVE-2023-28115 was disclosed | Sep 6, 2023 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Knplabs.
Media articles that mention a CVE ID that affects a product developed by Knplabs — matched by CVE ID, not by vendor name.